›› 2017, Vol. 30 ›› Issue (9): 169-.

• 论文 • 上一篇    

用于感知局域网攻击的离散事件系统研究

张冰冰   

  1. (黑龙江省电力医院 微机室,黑龙江 哈尔滨 150090)
  • 出版日期:2017-09-15 发布日期:2017-11-03
  • 作者简介:张冰冰(1983-),女,工程师。研究方向:计算机网络。

Research on Discrete Event System for LAN Attack

ZHANG Bingbing   

  1. (Computer Room,Heilongjiang Electric Power Hospital,Harbin 150090, China)
  • Online:2017-09-15 Published:2017-11-03

摘要:

由于地址解析协议(ARP)是无状态协议,且由主机发送的任何IP-MAC配对时在未经验证的情况下被接受,由此可能被局域网(LAN)中的恶意主机利用。针对该问题,文中提出了用于LAN攻击的入侵检测系统的离散事件系统。通过在ARP分组序列的基础上,在正常和攻击状态下为LAN建立离散事件系统模型;使用主动ARP检测以在正常和攻击状态下创建不同的ARP事件;随后,构建离散事件系统检测器,根据检测到的ARP事件确定LAN是否处于正常或攻击状态。文中所提出的方案在测试平台中被成功实现。

关键词: 局域网攻击, 离散事件系统, 地址解析协议, 网络安全

Abstract:

Since the Address Resolution Protocol (ARP) is a stateless protocol and any IP-MAC pair sent by the host is accepted without authentication, it may be exploited by malicious hosts in a local area network. To solve this problem, a discrete event system for intrusion detection system for LAN attack is proposed in this paper. Using the active ARP detection to create different ARP events in the normal and attack state; and then constructing the discrete event system detector to detect the ARP events in the normal and attack state; Determine whether the LAN is in a normal or attacked state based on the detected ARP events. The scheme proposed in this paper is successfully implemented in the test platform.

Key words: local area network attack, discrete event systems, address resolution protocol, network security

中图分类号: 

  • TN915.08